VendorsJuniperscreenosall versions
Vulnerabilities

Juniper Screenos

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

16CVEs
CVE-2015-7755
Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15b, 6.3.0r16 before 6.3.0r16b, 6.3.0r17 before 6.3.0r17b, 6.3.0r18 before 6.3.0r18b, 6.3.0r19 before 6.3.0r19b, and 6.3.0r20 before 6.3.0r21 allows remote attackers to obtain administrative access by entering an unspecified password during a (1) SSH or (2) TELNET session.
Published 2015-12-19 · Analyzed
10.0KEVEPSS 0.611
CVE-2017-2336
ScreenOS: XSS vulnerability in ScreenOS Firewall
Published 2017-07-14 · Modified
9.6EPSS 0.012
CVE-2015-7754
Juniper ScreenOS before 6.3.0r21, when ssh-pka is configured and enabled, allows remote attackers to cause a denial of service (system crash) or execute arbitrary code via crafted SSH negotiation.
Published 2016-01-08 · Modified
9.3EPSS 0.039
CVE-2017-2335
ScreenOS: XSS vulnerability in ScreenOS Firewall
Published 2017-07-14 · Modified
8.4EPSS 0.011
CVE-2017-2337
ScreenOS: XSS vulnerability in ScreenOS Firewall
Published 2017-07-14 · Modified
8.4EPSS 0.011
CVE-2017-2338
ScreenOS: XSS vulnerability in ScreenOS Firewall
Published 2017-07-14 · Modified
8.4EPSS 0.011
CVE-2017-2339
ScreenOS: XSS vulnerability in ScreenOS Firewall
Published 2017-07-14 · Modified
8.4EPSS 0.011
CVE-2014-2842
Juniper ScreenOS 6.3 and earlier allows remote attackers to cause a denial of service (crash and restart or failover) via a malformed SSL/TLS packet.
Published 2014-04-15 · Modified
7.8EPSS 0.035
CVE-2016-1268
The administrative web services interface in Juniper ScreenOS before 6.3.0r21 allows remote attackers to cause a denial of service (reboot) via a crafted SSL packet.
Published 2016-04-15 · Modified
7.8EPSS 0.019
CVE-2014-3813
Unspecified vulnerability in the Juniper Networks NetScreen Firewall products with ScreenOS before 6.3r17, when configured to use the internal DNS lookup client, allows remote attackers to cause a denial of service (crash and reboot) via vectors related to a DNS lookup.
Published 2014-06-13 · Modified
7.8EPSS 0.013
CVE-2014-3814
The Juniper Networks NetScreen Firewall devices with ScreenOS before 6.3r17, when configured to use the internal DNS lookup client, allows remote attackers to cause a denial of service (crash and reboot) via a sequence of malformed packets to the device IP.
Published 2014-06-13 · Modified
7.8EPSS 0.013
CVE-2013-6958
Juniper NetScreen Firewall running ScreenOS 5.4, 6.2, or 6.3, when the Ping of Death screen is disabled, allows remote attackers to cause a denial of service via a crafted packet.
Published 2013-12-13 · Modified
7.1EPSS 0.019
CVE-2018-0014
ScreenOS: Etherleak vulnerability found on ScreenOS device
Published 2018-01-10 · Modified
6.5EPSS 0.006
CVE-2013-7313
The OSPF implementation in Juniper Junos through 13.x, JunosE, and ScreenOS through 6.3.x does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet information via a crafted LSA packet, a related issue to CVE-2013-0149.
Published 2014-01-23 · Modified
5.4EPSS 0.011
CVE-2015-7756
The encryption implementation in Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15b, 6.3.0r16 before 6.3.0r16b, 6.3.0r17 before 6.3.0r17b, 6.3.0r18 before 6.3.0r18b, 6.3.0r19 before 6.3.0r19b, and 6.3.0r20 before 6.3.0r21 makes it easier for remote attackers to discover the plaintext content of VPN sessions by sniffing the network for ciphertext data and conducting an unspecified decryption attack.
Published 2015-12-19 · Modified
5.0EPSS 0.025
CVE-2015-7750
The L2TP packet processing functionality in Juniper Netscreen and ScreenOS Firewall products with ScreenOS before 6.3.0r13-dnd1, 6.3.0r14 through 6.3.0r18 before 6.3.0r18-dnc1, and 6.3.0r19 allows remote attackers to cause a denial of service via a crafted L2TP packet.
Published 2015-10-19 · Modified
5.0EPSS 0.020